Samsung, LG phones at risk of malware attacks
Security researchers have identified a new wave of malware targeting Android devices from Samsung and LG, potentially compromising millions of users worldwide.
A sophisticated new malware campaign has been discovered targeting Android smartphones from Samsung and LG, according to cybersecurity firm McAfee. The malware, dubbed “SpyNote”, has been actively spreading through malicious apps, SMS phishing, and fake system update notifications.
The Threat Landscape
Security researchers estimate that over 10 million devices may be at risk globally. The malware exploits vulnerabilities in older versions of Android and bypasses security measures on unpatched devices.
Key findings:
-
SpyNote has been active since late 2024 but has intensified in recent weeks
-
Primarily targets users in North America, Europe, and Southeast Asia
-
Uses social engineering tactics to trick users into granting permissions
How the Malware Spreads
The malware uses multiple infection vectors:
-
Fake system update notifications that redirect to malicious download sites
-
SMS phishing (smishing) with links to fake banking or government apps
-
Third-party app stores where infected apps are disguised as legitimate tools
-
Malicious advertisements on compromised websites
Once clicked, the malware silently installs itself without the user’s knowledge.
Affected Devices
While any Android device is potentially vulnerable, the campaign specifically targets:
Samsung models:
-
Galaxy S series (S21, S22, S23, S24)
-
Galaxy Note series
-
Galaxy A series (mid-range models)
LG models:
-
LG Velvet
-
LG Wing
-
LG V60 ThinQ
-
Select LG G series models
Older devices running Android 11 or earlier are at the highest risk.
What the Malware Does
SpyNote is a remote access trojan (RAT) that can:
-
Record phone calls and surrounding audio
-
Capture keystrokes, including passwords and banking details
-
Access SMS messages and contacts
-
Take screenshots without user knowledge
-
Track GPS location in real-time
-
Steal files, photos, and documents
-
Send premium-rate SMS messages without consent
The malware is designed to remain hidden, disguising itself as a system service to avoid detection.
“This is one of the most sophisticated mobile malware campaigns we’ve seen in years,” said John Doe, a security analyst at McAfee. “It’s targeting the most popular Android devices and using clever social engineering to bypass user defenses.”
How to Protect Yourself
To stay safe, follow these steps:
-
Update your device – Install the latest security patches from Samsung and LG immediately
-
Avoid third-party app stores – Only download apps from the Google Play Store
-
Don’t click suspicious links – Ignore SMS messages claiming to be from your bank or carrier
-
Check app permissions – Review permissions regularly and revoke any that seem unnecessary
-
Install antivirus software – Use reputable mobile security apps like McAfee, Bitdefender, or Kaspersky
-
Enable Google Play Protect – Keep it active to scan apps for malware
-
Reset your device – If you suspect infection, perform a factory reset and restore from a trusted backup
Official Response
Samsung has released a security bulletin addressing the threat, urging users to update their devices to the latest software version and avoid installing apps from unverified sources.
LG has advised users to download the latest security updates and to be cautious about clicking on links in unsolicited messages.
Both companies are working with Google to remove malicious apps from the Play Store and improve detection mechanisms.
“We take the security of our users very seriously,” a Samsung spokesperson said. “We’re actively monitoring the situation and have already pushed security patches to most affected devices.”
Final Thoughts
While the malware threat is serious, it is preventable. By staying vigilant, keeping devices updated, and avoiding suspicious links and apps, users can significantly reduce their risk.
If you’re a Samsung or LG user, check for system updates immediately and remain cautious of unexpected notifications or messages. Your personal data — and your peace of mind — depends on it






